CVE-2025-38342
published 2025-07-10CVE-2025-38342: In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args()…
high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
In the Linux kernel, the following vulnerability has been resolved:
software node: Correct a OOB check in software_node_get_reference_args()
software_node_get_reference_args() wants to get @index-th element, so
the property value requires at least '(index + 1) * sizeof(*ref)' bytes
but that can not be guaranteed by current OOB check, and may cause OOB
for malformed property.
Fix by using as OOB check '((index + 1) * sizeof(*ref) > prop->length)'.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 6.1.147-1 (bookworm) | linux 6.1.147-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.147-1 (bookworm) | linux 6.1.147-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 142acd739eb6f08c148a96ae8309256f1422ff4b | 142acd739eb6f08c148a96ae8309256f1422ff4b |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 56ce76e8d406cc72b89aee7931df5cf3f18db49d | 56ce76e8d406cc72b89aee7931df5cf3f18db49d |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 9324127b07dde8529222dc19233aa57ec810856c | 9324127b07dde8529222dc19233aa57ec810856c |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < f9397cf7bfb680799fb8c7f717c8f756384c3280 | f9397cf7bfb680799fb8c7f717c8f756384c3280 |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 4b3383110b6df48e0ba5936af2cb68d5eb6bd43b | 4b3383110b6df48e0ba5936af2cb68d5eb6bd43b |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 7af18e42bdefe1dba5bcb32555a4d524fd504939 | 7af18e42bdefe1dba5bcb32555a4d524fd504939 |
| linux | linux | >= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 31e4e12e0e9609850cefd4b2e1adf782f56337d6 | 31e4e12e0e9609850cefd4b2e1adf782f56337d6 |
| linux | linux_kernel | >= 0 < 5.10.244-1 | 5.10.244-1 |
| linux | linux_kernel | >= 0 < 6.1.147-1 | 6.1.147-1 |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 0 < 5.15.0-156.166 | 5.15.0-156.166 |
| linux | linux_kernel | >= 0 < 6.8.0-100.100 | 6.8.0-100.100 |
| linux | linux_kernel | >= 5.0 < 5.10.239 | 5.10.239 |
| linux | linux_kernel | >= 5.11 < 5.15.186 | 5.15.186 |
| linux | linux_kernel | >= 5.16 < 6.1.142 | 6.1.142 |
| linux | linux_kernel | >= 6.13 < 6.15.4 | 6.15.4 |
| linux | linux_kernel | >= 6.2 < 6.6.95 | 6.6.95 |
| linux | linux_kernel | >= 6.7 < 6.12.35 | 6.12.35 |
| msrc | azl3_kernel_6.6.92.2-2_on_azure_linux_3.0 | — | — |
| ubuntu | linux-aws | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH